Skip to content

Build: Bump org.apache.avro:avro from 1.12.0 to 1.12.1 (#14369)#15607

Merged
amogh-jahagirdar merged 2 commits into
apache:1.10.xfrom
steveloughran:pr/1.10.x+avro
Mar 14, 2026
Merged

Build: Bump org.apache.avro:avro from 1.12.0 to 1.12.1 (#14369)#15607
amogh-jahagirdar merged 2 commits into
apache:1.10.xfrom
steveloughran:pr/1.10.x+avro

Conversation

@steveloughran

@steveloughran steveloughran commented Mar 12, 2026

Copy link
Copy Markdown
Contributor

Fixes #15606

Addresses CVE-2025-33042

Bumps org.apache.avro:avro from 1.12.0 to 1.12.1.


updated-dependencies:

  • dependency-name: org.apache.avro:avro dependency-version: 1.12.1 dependency-type: direct:production update-type: version-update:semver-patch ...

Signed-off-by: dependabot[bot] support@github.com
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

cherrypick of 4cea662

Addresses CVE-2025-33042

Bumps org.apache.avro:avro from 1.12.0 to 1.12.1.

---
updated-dependencies:
- dependency-name: org.apache.avro:avro
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

cherrypick of 4cea66
@amogh-jahagirdar

Copy link
Copy Markdown
Contributor

Thanks @steveloughran I think we'll also need to update the LICENSE here ?

Group: org.apache.avro Name: avro Version: 1.12.0

@ebyhr

ebyhr commented Mar 12, 2026

Copy link
Copy Markdown
Member

cherrypick of 4cea66

It seems the GitHub web UI doesn't provide a link to the corresponding commit when using an abbreviated hash. We could instead replace it with something like:

(cherry picked from commit 4cea662253f440366e0358d1cadae36004d883b5)

@ebyhr

ebyhr commented Mar 12, 2026

Copy link
Copy Markdown
Member

kafka-connect/kafka-connect-runtime/hive/LICENSE & kafka-connect/kafka-connect-runtime/main/LICENSE also have Group: org.apache.avro Name: avro Version: 1.12.0 line in 1.10.x branch.

@steveloughran

Copy link
Copy Markdown
Contributor Author

let me review the LICENSE.

@steveloughran

steveloughran commented Mar 13, 2026

Copy link
Copy Markdown
Contributor Author

w.r.t licenses; I'll add a commit to fix that, which is also needed on main branch

@amogh-jahagirdar amogh-jahagirdar left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @steveloughran, I'll go ahead and merge. Thank you @singhpk234 @huaxingao @ebyhr for reviewing

@amogh-jahagirdar amogh-jahagirdar merged commit 58e86c7 into apache:1.10.x Mar 14, 2026
43 checks passed
@steveloughran steveloughran deleted the pr/1.10.x+avro branch May 5, 2026 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants